Sentinelas · Legal
Last updated: August 26, 2026
Privacy Policy
Scope and controller
This Privacy Policy applies to the Sentinelas macOS application, its headless CLI, and its public product pages, including downloads and legal documentation (together, the “Sentinelas Services”).
Viralizai, LLC (“Viralizai,” “we,” “us”) is responsible for the limited data it receives directly through these services. Data processed by an executor CLI, model provider, messaging channel, or other integration you choose is also governed by that third party's policies.
Data that stays on your Mac
Your fleet is stored locally. Sentinelas does not send the operational content of your sentinels to the maintainer. The stable compatibility root is ~/sentinelas and may point through an absolute symlink to another physical folder you choose. Manuals live in the executor CLI's agent directory.
- Manuals, state, queues, completed items, history, approvals, groups, favorites, and schedules.
- Execution logs, resume commands, and session metadata maintained by compatible CLIs.
- Public variables in env/, private secrets in secrets/, and the full license key in macOS Keychain.
- Version history snapshots and the auto-observe ledger when that feature is enabled.
Application usage analytics
In distribution builds, Sentinelas may send anonymous interface usage events to PostHog to understand reliability and improve the experience. This option starts enabled and can be turned off at any time in Settings → Privacy. Development builds start with collection disabled, and the headless CLI never initializes the analytics SDK.
Events come from a closed catalog in the code and may include app and macOS version, language, plan, sentinel and screen counts, how the panel was opened, generic routes and actions, toggle states, and, only for installs from the public catalog, the catalog entry name and selected CLI. PostHog is configured without person profiles and without automatic screen or application lifecycle capture.
- We never send names of sentinels you create, group names, or local paths.
- We never send the contents of manuals, memory, logs, sessions, queues, approvals, environment variables, or secrets.
- Error reasons sent by the app are generic tokens, not raw messages that could contain local context.
Data from Sentinelas web pages
On public production pages, we use Vercel Web Analytics and Speed Insights to measure visits and performance. These services may process the route and URL visited, referring page, approximate country, browser, operating system, device type, network speed, event time, and Web Vitals. Vercel Web Analytics does not use cookies and derives a daily identifier that does not track a person across websites or days.
The waitlist asks for a name and email address. By submitting the form, you agree to receive Sentinelas news; this data is sent to Mailchimp to manage the list, double opt-in, and communications. You can unsubscribe through the link included in those emails.
As with any website, hosting infrastructure may receive technical request data such as an IP address and user agent to deliver and secure the service. Preferences such as theme may be stored locally by your browser. Sentinelas pages do not use behavioral advertising cookies.
Pro license and purchases
Checkout is operated by Polar, which acts as merchant of record and processes payment, tax, receipts, and buyer details under its own policy. Sentinelas does not receive or store your full payment card number.
During activation, the app sends Polar's license endpoint the key, public organization identifier, a device label, the Mac's IOPlatformUUID as an activation condition, and technical activation metadata. The license is revalidated in the background, generally every 24 hours.
- The full key stays in macOS Keychain and is read only during activation, revalidation, and deactivation inside the app.
- The local license.json stores only the masked key, status, dates, and activation/device identifiers needed for the offline gate.
- When you deactivate, the app attempts to release the device at Polar and always removes the local license. Polar's commercial records follow its own policy and legal retention periods.
Executor CLIs and integrations you choose
Sentinelas schedules and launches agent CLIs you install, such as Claude, Kimi, Codex, Copilot, Qwen, Gemini, and Droid. The app does not proxy these providers. To execute a manual, a CLI may transmit prompts, code excerpts, files, tool results, or other context to its model provider according to that provider's account settings and policies.
A sentinel may also call GitHub, Discord, Telegram, Slack, ntfy, MCP services, APIs, or any other destination authorized by its manual and configuration. In that case, the third party receives the data the automation sends. Review the manual, permissions, and destination policies before enabling a schedule.
- Public variables are readable by the sentinel; do not put anything there that the agent should not see.
- Private secrets are stored in permission-restricted files and read by specific helpers. Deny rules add a barrier against direct access, but they do not replace the security of your local account or provider permissions.
- Credentials may be transmitted to the service you choose to authenticate a request, but Sentinelas does not send them to the maintainer.
“Local” means Viralizai does not receive your fleet. It does not mean that an AI CLI or integration you configure works without a network connection.
Auto-observe
Auto-observe is an optional Pro feature. When enabled, Sentinelas installs SessionEnd hooks in Claude and Kimi settings. On clean session endings that contain a real user turn, the hook stores the timestamp, CLI, session identifier, working directory, and transcript path locally. It does not copy conversation content into the ledger.
After the threshold you choose is reached, the local analyzer may open the referenced transcripts and use the executor CLI to identify repeated work. This means that CLI's provider may process the context read, under your account settings. Each batch creates at most one proposal, always paused and waiting for approval.
- Turning the feature off removes the hooks but preserves existing ledgers and proposals until you delete them.
- Abruptly terminated sessions, sentinel sessions, and sessions without a real user turn are excluded when the CLI makes that distinction possible.
- Auto-observe must never copy tokens, passwords, or ENV values into a proposed manual.
Local security and the integration server
We apply local controls such as 0600 files, a 0700 secrets directory, Keychain, deny rules, execution locks, and merge writes. The integration server binds only to 127.0.0.1:7467 and is not exposed to the external network.
The local API does not use authentication. Any process with access to your local session and loopback may attempt to call supported routes to trigger, approve, or update queues. Keep your macOS account, installed software, and local integrations secure. The keep-awake feature uses a sudo authorization limited to the documented pmset commands and does not send power status to Viralizai.
Retention and your controls
You control local data and may edit or remove sentinels, logs, queues, history, ledgers, and the fleet's physical root. Uninstalling the app does not automatically erase files in ~/sentinelas or manuals in CLI folders, preventing silent data loss.
When you disable app analytics, new events stop being sent; data already received remains subject to the retention configured in PostHog. Web page, email-list, and checkout data follow Vercel's, Mailchimp's, and Polar's policies, respectively. We keep data under our control only as long as needed for the purposes described, legal obligations, security, and dispute resolution.
Legal bases and sharing
Depending on applicable law, we process data to perform our contract and deliver the product, comply with legal duties, secure the services and prevent fraud, pursue legitimate interests in improvement and reliability, or with your consent when required.
We do not sell personal data or the contents of your sentinels. We share data only with necessary providers, currently Polar for checkout and licensing, PostHog for optional app analytics, Vercel for hosting, web analytics, and performance, and Mailchimp for the waitlist, or when required by law. Providers you choose directly do not act under our instructions merely because a sentinel launches them.
International transfers and children
Viralizai is a United States company, and our providers may process data in the United States and other countries. Where applicable, we rely on the contractual mechanisms and safeguards offered by providers and required by law.
The Sentinelas Services are intended for professionals and are not directed to children under 18. We do not knowingly collect children's data. If you believe a child has provided personal data to us, contact us so we can evaluate and remove it.
Your rights, changes, and contact
Depending on where you live, you may request confirmation, access, correction, deletion, portability, or restriction, and may object or withdraw consent. Because most fleet data never reaches us, many controls are exercised directly on your Mac. We may need to verify your identity before responding to a request about data under our control.
We may update this policy to reflect changes in the product, providers, or law. Material changes will receive a new date and, when necessary, renewed consent in the app. For questions, privacy requests, or complaints, email suporte@viralizai.co. You may also contact the competent data protection authority in your region.
Policies and contact
You can also review the documents of providers that process data for specific Sentinelas functions.